PT-2021-4655 · Cisco · Cisco Ios Xe
Published
2021-09-22
·
Updated
2021-10-05
·
CVE-2021-1625
CVSS v3.1
5.8
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco IOS XE Software (affected versions not specified)
Description
The issue is related to the Zone-Based Policy Firewall feature of Cisco IOS XE Software, where insufficient access control restrictions when configuring Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) can be exploited. An unauthenticated, remote attacker could send ICMP or UDP packets to bypass security restrictions, potentially allowing traffic to be incorrectly classified or dropped. This could also result in incorrect reporting figures produced by high-speed logging (HSL).
Recommendations
For Cisco IOS XE Software, update to a version that includes the fix for this issue, as software updates have been released by Cisco to address this vulnerability.
As a temporary workaround, consider restricting access to the Zone-Based Policy Firewall feature until a patch is available.
Avoid using the Unified Threat Defense (UTD) or Application Quality of Experience (AppQoE) configurations in the Zone-Based Policy Firewall until the issue is resolved.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Ios Xe